yaws records
11 published records for vendor yaws.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 9.1%
- Pre-auth RCE
- 2
- With a fix record
- 81.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-326 Inadequate Encryption Strength1
- CWE-399 Resource Management Errors1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
54Plan | CVE-2017-10974Proof of concept | Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080.yaws · yaws · CWE-22 | High7.5 | — | 81.2% | Jul 7, 2017 |
44Plan | CVE-2020-24916No exploit | CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.yaws · yaws · CWE-78 | Critical9.8 | — | 17.4% | Sep 9, 2020 |
40Plan | CVE-2020-24379No exploit | WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.yaws · yaws · CWE-611 | Critical9.8 | — | 3.4% | Sep 9, 2020 |
31Monitor | CVE-2011-4350Weaponized | Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed.yaws · yaws · CWE-22 | Medium6.5 | — | 16.1% | Nov 26, 2019 |
24Monitor | CVE-2016-1000108No exploit | yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications fryaws · yaws · CWE-601 | Medium6.1 | — | 1.1% | Dec 10, 2019 |
23Monitor | CVE-2009-0751Proof of concept | Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of heyaws · yaws · CWE-399 | Medium5.0 | — | 10.4% | Mar 2, 2009 |
23Monitor | CVE-2009-4495Proof of concept | Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's tityaws · yaws · CWE-20 | Medium5.0 | — | 9.0% | Jan 13, 2010 |
23Monitor | CVE-2010-4181Proof of concept | Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequencyaws · yaws · CWE-22 | Medium5.0 | — | 8.5% | Nov 4, 2010 |
22Monitor | CVE-2020-12872No exploit | yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if runninyaws · yaws · CWE-326 | Medium5.5 | — | 0.4% | May 15, 2020 |
20Monitor | CVE-2005-2008No exploit | Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a traiyaws · webserver | Medium5.0 | — | 1.5% | Jun 17, 2005 |
18Monitor | CVE-2011-5025Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web scriyaws · yaws · CWE-79 | Medium4.3 | — | 2.7% | Dec 29, 2011 |
- CVE-2017-1097454Plan
Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080.
HighCVSS 7.5Proof of conceptEPSS 81%yaws · yawsJul 7, 2017
- CVE-2020-2491644Plan
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
CriticalCVSS 9.8No exploitEPSS 17%yaws · yawsSep 9, 2020
- CVE-2020-2437940Plan
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
CriticalCVSS 9.8No exploitEPSS 3%yaws · yawsSep 9, 2020
- CVE-2011-435031Monitor
Yaws 1.91 has a directory traversal vulnerability in the way certain URLs are processed.
MediumCVSS 6.5WeaponizedEPSS 16%yaws · yawsNov 26, 2019
- CVE-2016-100010824Monitor
yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications fr
MediumCVSS 6.1No exploitEPSS 1%yaws · yawsDec 10, 2019
- CVE-2009-075123Monitor
Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with a large number of he
MediumCVSS 5.0Proof of conceptEPSS 10%yaws · yawsMar 2, 2009
- CVE-2009-449523Monitor
Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to modify a window's tit
MediumCVSS 5.0Proof of conceptEPSS 9%yaws · yawsJan 13, 2010
- CVE-2010-418123Monitor
Directory traversal vulnerability in Yaws 1.89 allows remote attackers to read arbitrary files via ..\ (dot dot backslash) and other sequenc
MediumCVSS 5.0Proof of conceptEPSS 8%yaws · yawsNov 4, 2010
- CVE-2020-1287222Monitor
yaws_config.erl in Yaws through 2.0.2 and/or 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks, if runnin
MediumCVSS 5.5No exploitEPSS 0%yaws · yawsMay 15, 2020
- CVE-2005-200820Monitor
Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trai
MediumCVSS 5.0No exploitEPSS 1%yaws · webserverJun 17, 2005
- CVE-2011-502518Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the wiki application in Yaws 1.88 allow remote attackers to inject arbitrary web scri
MediumCVSS 4.3Proof of conceptEPSS 3%yaws · yawsDec 29, 2011